Source · DiggingBeagle record
Mandiant AI Risk and Resilience Report 2026 - Case study 1
Primary Google Cloud/Mandiant report documenting an intrusion at an unnamed SaaS provider in which an attacker hijacked an active AI coding-assistant session, introduced poisoned software through the assistant's recommendation path, harvested GitHub OAuth tokens and spread Shai-Hulud across about 100 internal repositories.
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Primary Google Cloud/Mandiant report documenting an intrusion at an unnamed SaaS provider in which an attacker hijacked an active AI coding-assistant session, introduced poisoned software through the assistant's recommendation path, harvested GitHub OAuth tokens and spread Shai-Hulud across about 100 internal repositories.
Claim-level citations (5)
- supportsHijacked AI coding-assistant session became the entry path for Shai-Hulud across about 100 repositories: After acceptance, Mandiant says the attacker used the active session to install an infostealer through a poisoned PyPI package, harvest GitHub OAuth tokens and deploy Shai-Hulud across approximately 100 internal code repositories.
Case study 1, paragraph beginning 'Once the recommendation was accepted'
- supportsHijacked AI coding-assistant session became the entry path for Shai-Hulud across about 100 repositories: The attacker then poisoned a package inside the organization's official namespace, and another employee pulling the compromised version caused a secondary downstream infection.
Case study 1, paragraph beginning 'The actor then poisoned a package inside the organisation's official namespace'
- supportsHijacked AI coding-assistant session became the entry path for Shai-Hulud across about 100 repositories: Mandiant says the Shai-Hulud worm automated theft of repository secrets and programmatic exfiltration of proprietary product source code.
Case study 1, paragraph describing Shai-Hulud deployment and automated theft/exfiltration
- supportsHijacked AI coding-assistant session became the entry path for Shai-Hulud across about 100 repositories: Mandiant says a threat actor compromised an unnamed SaaS provider and hijacked an active AI coding-assistant session on a developer workstation.
Case study 1, paragraph beginning 'Mandiant investigated a sophisticated intrusion'
- supportsHijacked AI coding-assistant session became the entry path for Shai-Hulud across about 100 repositories: The hijacked assistant recommended installation of an external software package poisoned by the attacker; after the recommendation was accepted, the assistant's trusted workflow facilitated malicious software installation.
Case study 1, paragraphs describing the poisoned external package and accepted recommendation
Cite this record
DiggingBeagle. “Mandiant AI Risk and Resilience Report 2026 - Case study 1.” https://diggingbeagle.com/sources/mandiant-ai-risk-and-resilience-report-2026-case-study-1/
Citation guidance